OpenAPPA: New Security Engine Achieves 0% Attack Success in Multi-Step Enterprise Workflows
October 4, 2026
OpenAPPA operates outside the agent’s prompt and execution loop, defined by a configuration file (appa.toml) that specifies data sources, audiences, trust levels, and authorities, plus deterministic security enforcement rules.
Ablation experiments show that removing remedy plans dramatically lowers task completion, from 89% to 35%, underscoring the importance of recovery mechanisms.
The project provides formal algebra and recovery guarantees, with an arXiv publication and a GitHub preview of OpenAPPA, along with comprehensive project documentation.
Bench-Corp tested 20 multi-step enterprise workflows, while AgentThreatBench applies the OWASP Top 10 for Agentic Applications; together they evaluate both utility and security.
Each tool contract details attributes like requirements, delta restrictions, and effects to enable fine-grained access control—for example, get_ticket_from_crm restricts audiences to internal users, while publish_update requires a public audience.
In benchmarks, OpenAPPA achieved 0% attack success with 89% task completion, outperforming Claude Code’s auto mode (10% attack, 90% completion) and Microsoft FIDES (31% attack, 41% completion).
The system uses an Agentic Permissions Policy Algebra to label policies for audience and trust, with reading restrictions narrowing audiences and reading unvetted pages lowering trust.
OpenAPPA includes recovery semantics: on illegal actions it halts dispatch, offers remediation paths, sanitizes data to expand permitted audiences, and routes requests to human operators for single-action approvals; Disposable Child Branches isolate untrusted reads in transient subagent branches.
OpenAPPA, an open-source security engine from Archestra, blocks data exfiltration from prompt injection and model hallucination, released on October 3, 2026.
Summary based on 1 source
